Plaintext Private Key Exposure in Arista EOS Devices
CVE-2026-73465

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-73465?

In specific conditions on Arista EOS devices, certain non-standard debugging trace levels may lead to the writing of plaintext private keys to log files. This situation necessitates authenticated local administrative access to the device shell, and the explicit enabling of special debugging modes. Although identified internally by Arista, no evidence of exploitation has been discovered in customer environments, highlighting the importance of secure logging practices and access controls.

Affected Version(s)

EOS 4.36.0 <= 4.36.1F

EOS 4.35.0 <= 4.35.4M

EOS 4.34.0 <= 4.34.7M

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.